- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello,
in the last few weeks I have had an abnormal increase in resource consumption. I leave attached the screens of the consumption of ram (constantly increasing) and cpu. All this happened on the 30th of last month, when there was the scheduled log cleaning activity. In addition to the use of the cpu and ram, I noticed the increase in connections, it only increased by about 1 Mbps in the sync board towards the standby node. I asked for my assistance but they could not understand the problem. resource consumption has always remained stable and now it has gone up all of a sudden and it stays there ... the ram is going up very fast until it is saturated and the problems will start ... I have to understand the problem before that.
PS: the cpu in some graphics is very low because it averages all 12 cpus, when my license allows me to use only 4.
any suggestions?
thank you.
Did you reboot the unit in question already ?
What version/JHF level?
Also, please provide output of the Super Seven commands: https://community.checkpoint.com/t5/Scripts/S7PAC-Super-Seven-Performance-Assessment-Commands/m-p/40...
Everything looks fine to me, your firewall is not paging or swapping due to a shortage of free memory as shown by top.
Looks like normal utilization of excess memory for buffering/caching that grows over time, but that memory can be freed instantly if it is needed for code execution which happened a few times and caused the sudden drop in memory utilization in your graph. After a reboot memory utilization will look much lower and slowly grow as it is utilized for buffering/caching; this is expected and welcome behavior as long as your firewall is not dipping into swap space.
As Phoneboy said we need to see Super Seven outputs, especially free -m.
The fact you have a lot of drops on eth1 is concerning and could very well be the cause of increased CPU.
Where precisely does eth1 lead?
Also, the fact you have 12 cores but are licensed for 4 means you're not able to fully utilize your appliance.
Like @Timothy_Hall said, increasing memory utilization is not necessarily indicative of an issue.
As Phoneboy observed there are some drops on eth1 and eth3 but they are well below 0.1% of total frames and not an immediate concern, your single SND core in the 1/3 split is also relatively idle compared your 3 firewall worker cores which are running around 60% utilization. Not a huge amount of headroom available there and I'd agree with Phoneboy that you may want to consider licensing 8 cores which would move you to a 2/6 split.
Your 27% F2F traffic percentage is a bit high but not ridiculous, please provide the output of enabled_blades which may explain some of that. Everything else looks fine to me...
[Expert@*******:0]# enabled_blades
fw vpn cvpn urlf appi ips identityServer SSL_INSPECT anti_bot mon vpn
I understand that I have few resources available but I ask you please to look again at the screen I am attaching, that sudden increase in resources It is something strange. It is not possible for an appliance to run for months and months with regular resource consumption, there is a definite pattern. and then suddenly, BOOM, from the 29th there is a SUBSTANTIVE increase in resources. it is anomalous, no doubt about it
I would suggest a reboot or failover - an uptime of more than a month is not good for a GW 8).
@G_W_Albrecht not relevant to the topic of the tread, but I would disagree that you would need to restart GW every month, seems a bit excessive to me. Just for fun comment, back in the day we had a Nokia IP440 box with uptime over 3500 days! no memory issues... 🙂 SW in IPSO was top notch!
OK, i admit that current CP GAiA based GWs need only to be rebooted about once every quarter 😏
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 27 | |
| 23 | |
| 15 | |
| 13 | |
| 12 | |
| 10 | |
| 6 | |
| 6 | |
| 5 | |
| 4 |
Fri 14 Nov 2025 @ 10:00 AM (CET)
CheckMates Live Netherlands - Veriti, Threat Exposure ManagementWed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERFri 14 Nov 2025 @ 10:00 AM (CET)
CheckMates Live Netherlands - Veriti, Threat Exposure ManagementWed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY